Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Dec 3, 2025

This PR contains the following updates:

Package Type Update Change OpenSSF
next (source) dependencies patch 16.0.6 -> 16.0.7 OpenSSF Scorecard

GitHub Vulnerability Alerts

CVE-2025-66478

A vulnerability affects certain React packages1 for versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 and frameworks that use the affected packages, including Next.js 15.x and 16.x using the App Router. The issue is tracked upstream as CVE-2025-55182.

Fixed in:
React: 19.0.1, 19.1.2, 19.2.1
Next.js: 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

The vulnerability also affects experimental canary releases starting with 14.3.0-canary.77. Users on any of the 14.3 canary builds should either downgrade to a 14.x stable release or 14.3.0-canary.76.

All users of stable 15.x or 16.x Next.js versions should upgrade to a patched, stable version immediately.

1 The affected React packages are:

  • react-server-dom-parcel
  • react-server-dom-turbopack
  • react-server-dom-webpack

Release Notes

vercel/next.js (next)

v16.0.7

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.


Summary by cubic

Upgraded Next.js from 16.0.6 to 16.0.7 to fix CVE-2025-66478 affecting React Server DOM packages with the App Router. This applies the upstream security patch; no code changes needed.

  • Dependencies
    • Refreshed platform-specific @next/swc binaries in bun.lock to match Next 16.0.7.

Written for commit f433f5d. Summary will update automatically on new commits.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
@renovate renovate bot added the dependencies Dependency updates label Dec 3, 2025
@renovate renovate bot enabled auto-merge (squash) December 3, 2025 22:34
@renovate renovate bot added the dependencies Dependency updates label Dec 3, 2025
Copy link

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 2 files

@github-actions github-actions bot added qa:running QA workflow is currently running qa:success QA workflow passed successfully status:ready-for-review Pull request is ready for review status:mergeable Pull request is approved, tests pass, and ready to merge and removed qa:running QA workflow is currently running status:ready-for-review Pull request is ready for review labels Dec 3, 2025
@renovate renovate bot merged commit 1348c2c into main Dec 3, 2025
11 checks passed
@renovate renovate bot deleted the renovate/npm-next-vulnerability branch December 3, 2025 22:45
@github-actions github-actions bot added status:merged Pull request has been merged status:mergeable Pull request is approved, tests pass, and ready to merge and removed status:mergeable Pull request is approved, tests pass, and ready to merge status:merged Pull request has been merged labels Dec 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates qa:success QA workflow passed successfully status:mergeable Pull request is approved, tests pass, and ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant